CVE-2016-6934: XSS
Adobe Experience Manager Forms versions 6.2 and earlier, LiveCycle 11.0.1, LiveCycle 10.0.4 have an input validation issue in the PMAdmin module that could be used in cross-site scripting attacks.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6934?
CVE-2016-6934 is classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
How do I fix CVE-2016-6934?
To mitigate CVE-2016-6934, update to Adobe Experience Manager Forms version 6.3 or later, or upgrade to Adobe LiveCycle version 11.0.2.
What are the affected versions for CVE-2016-6934?
CVE-2016-6934 affects Adobe Experience Manager Forms versions up to 6.2, Adobe LiveCycle version 10.0.4, and version 11.0.1.
What type of attack can be executed due to CVE-2016-6934?
CVE-2016-6934 can be exploited to perform cross-site scripting (XSS) attacks.
Which module is vulnerable in CVE-2016-6934?
The PMAdmin module in Adobe Experience Manager Forms and LiveCycle is the component with input validation issues in CVE-2016-6934.